{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:QK4DWUDAOI3Q7R6QDSBBT5PNG6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"89508ee99d0011efe14d1fd4fdf081b0f6082f943424de3111e9ece4b4f62511","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-13T15:35:12Z","title_canon_sha256":"849ced78a970a8c2e685b3cfa601c3ffafc4c618ce39a900a496f555b2f4a79c"},"schema_version":"1.0","source":{"id":"2605.13676","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.13676","created_at":"2026-05-18T02:44:17Z"},{"alias_kind":"arxiv_version","alias_value":"2605.13676v1","created_at":"2026-05-18T02:44:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.13676","created_at":"2026-05-18T02:44:17Z"},{"alias_kind":"pith_short_12","alias_value":"QK4DWUDAOI3Q","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"QK4DWUDAOI3Q7R6Q","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"QK4DWUDA","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:5dff58e4d2716bfce0aedad318e84f4a7fdab5ef13536e707598861213e47cd5","target":"graph","created_at":"2026-05-18T02:44:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"EBCC can make TEE-backed execution manageable through an OCI-style lifecycle without materially enlarging the protected-side TCB."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The backend adapter and lifecycle mediation preserve isolation and do not introduce new attack surfaces or require post-hoc security assumptions beyond standard TEE guarantees."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"EBCC provides an OCI-compatible runtime architecture that unifies REE and TEE stages for confidential containers while preserving standard lifecycle operations behind a backend adapter."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"EBCC lets TEE-backed confidential containers follow the standard OCI lifecycle without enlarging the protected TCB."}],"snapshot_sha256":"6af2298283139413f2e35da5c8014cb1ddc2b5844faa67258f34b5b939a7952a"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Container runtimes provide a stable operational interface for deploying, monitoring, and controlling modern workloads, while trusted execution environments (TEEs) provide hardware-enforced isolation for sensitive computation. Existing confidential-container systems often rely on VM-backed deployment stacks or TEE-specific execution substrates, which can separate confidential execution from the conventional OCI runtime lifecycle. This paper presents EBCC (Enclave-Backed Confidential Containers), an OCI-compatible runtime architecture for managing composite confidential-computing workloads. EBCC","authors_text":"Di Lu, Jianfeng Ma, Qingwen Zhang, Xuewen Dong, Yujia Liu, Yulong Shen, Zhiquan Liu","cross_cats":[],"headline":"EBCC lets TEE-backed confidential containers follow the standard OCI lifecycle without enlarging the protected TCB.","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-13T15:35:12Z","title":"EBCC: Enclave-Backed Confidential Containers via OCI-Compatible Runtime Integration"},"references":{"count":63,"internal_anchors":2,"resolved_work":63,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Crossing shifted moats: Replacing old bridges with new tunnels to confidential containers,","work_id":"28cc8839-7512-4ed7-aad1-6ad9913d3b4c","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Serverless confidential containers: Challenges and experiences,","work_id":"73fbac01-397c-4ab0-a484-dde56252dd28","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Scone: Secure linux containers with intel sgx,","work_id":"a18f6795-f102-48aa-b4c5-453d16318b57","year":2016},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Occlum: Secure and efficient multitasking inside a single enclave of intel sgx,","work_id":"1270d896-5637-4660-8f87-ce60a5a76246","year":2020},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Graphene-sgx: A practical library os for unmodified applications on sgx,","work_id":"16cf991c-7347-4838-a050-3fedf1f36736","year":2017}],"snapshot_sha256":"d204613bbb3734e47754a6f7858b129dea446801d32f90edd08dfd1cfb85a643"},"source":{"id":"2605.13676","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-14T18:01:49.441092Z","id":"23ae248e-60f7-406f-8fd2-006958108b64","model_set":{"reader":"grok-4.3"},"one_line_summary":"EBCC provides an OCI-compatible runtime architecture that unifies REE and TEE stages for confidential containers while preserving standard lifecycle operations behind a backend adapter.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"EBCC lets TEE-backed confidential containers follow the standard OCI lifecycle without enlarging the protected TCB.","strongest_claim":"EBCC can make TEE-backed execution manageable through an OCI-style lifecycle without materially enlarging the protected-side TCB.","weakest_assumption":"The backend adapter and lifecycle mediation preserve isolation and do not introduce new attack surfaces or require post-hoc security assumptions beyond standard TEE guarantees."}},"verdict_id":"23ae248e-60f7-406f-8fd2-006958108b64"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4de9f146d039a53cf0752701f6cb9426a667f331649da011dd0f897d7b5334f1","target":"record","created_at":"2026-05-18T02:44:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"89508ee99d0011efe14d1fd4fdf081b0f6082f943424de3111e9ece4b4f62511","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-13T15:35:12Z","title_canon_sha256":"849ced78a970a8c2e685b3cfa601c3ffafc4c618ce39a900a496f555b2f4a79c"},"schema_version":"1.0","source":{"id":"2605.13676","kind":"arxiv","version":1}},"canonical_sha256":"82b83b506072370fc7d01c8219f5ed3792cc002b30cfdc47887bff813ef038ed","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"82b83b506072370fc7d01c8219f5ed3792cc002b30cfdc47887bff813ef038ed","first_computed_at":"2026-05-18T02:44:17.094818Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T02:44:17.094818Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"zEFiMgJZ//0DkgJgjQ7DINGG5hJTOXRop3QhJTJQ/nvUi8oxaJijUZjiA4KsEaeKNIcv2OvI37yqfUxAAih1Cw==","signature_status":"signed_v1","signed_at":"2026-05-18T02:44:17.095408Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.13676","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4de9f146d039a53cf0752701f6cb9426a667f331649da011dd0f897d7b5334f1","sha256:5dff58e4d2716bfce0aedad318e84f4a7fdab5ef13536e707598861213e47cd5"],"state_sha256":"94eb94f4de83c34517cbdefa68372ac77ed95d9ce55862c23c9f633a5abb6ba9"}